slackware-current/source/installer/sources/dropbear/dropbear_emptypass.patch
Patrick J Volkerding b893b1174d Thu Jun 21 05:18:41 UTC 2018
a/kernel-generic-4.14.51-x86_64-1.txz:  Upgraded.
a/kernel-huge-4.14.51-x86_64-1.txz:  Upgraded.
a/kernel-modules-4.14.51-x86_64-1.txz:  Upgraded.
d/kernel-headers-4.14.51-x86-1.txz:  Upgraded.
d/parallel-20180622-noarch-1.txz:  Upgraded.
k/kernel-source-4.14.51-noarch-1.txz:  Upgraded.
l/libedit-20180525_3.1-x86_64-1.txz:  Upgraded.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
2018-06-21 19:27:50 +02:00

20 lines
783 B
Diff

diff -Nur dropbear-20171018_fa3b0dd3.orig/svr-authpasswd.c dropbear-20171018_fa3b0dd3/svr-authpasswd.c
--- dropbear-20171018_fa3b0dd3.orig/svr-authpasswd.c 2018-01-13 19:19:59.000000000 -0600
+++ dropbear-20171018_fa3b0dd3/svr-authpasswd.c 2018-01-13 23:07:16.441369958 -0600
@@ -88,12 +88,16 @@
}
/* check for empty password */
+ /* Yep, good idea, but for our usage, it's okay - dropbear has to be
+ started manually in the installer, so setting a password or not is
+ up to the admin
if (passwdcrypt[0] == '\0') {
dropbear_log(LOG_WARNING, "User '%s' has blank password, rejected",
ses.authstate.pw_name);
send_msg_userauth_failure(0, 1);
return;
}
+ */
if (constant_time_strcmp(testcrypt, passwdcrypt) == 0) {
/* successful authentication */